ligolo-ng

Fail

Audited by Snyk on Apr 16, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt includes an explicit plaintext credential example (e.g., "evil-winrm -i ... -u admin -p pass") and demonstrates passing passwords on the command line, which requires embedding secrets verbatim in generated commands/outputs.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This skill documents an explicit reverse-tunneling backdoor (proxy + agent) intended to be deployed on a compromised pivot host (including instructions to upload/run agents, ignore TLS certs, enable persistence/Windows service install, create TUN interfaces, and add port-forwarding) — behavior that directly enables unauthorized remote access, lateral movement, and data exfiltration.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs privileged system modifications—creating TUN interfaces, running sudo ip tuntap/ip link/ip route commands, starting privileged listeners, and references agent persistence/Windows service install—so it directs the agent to change the machine's state and require/seek elevated privileges.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 16, 2026, 08:20 PM
Issues
3
Security Audit — snyk — ligolo-ng